Title :
Evaluation of Online Resources in Assisting Phishing Detection
Author :
Bian, Kaigui ; Park, Jung-Min ; Hsiao, Michael S. ; Bélanger, France ; Hiller, Janine
Author_Institution :
Dept. of Electr. & Comput. Eng., Virginia Tech, Blacksburg, VA, USA
Abstract :
Phishing is an attempt to fraudulently acquire userspsila sensitive information, such as passwords or financial information, by masquerading as a trustworthy entity in online transactions. Recently, a number of researchers have proposed using external online resources like the Google Page Rank system to assist phishing detection. The advantage of such an approach is that the detection capability will gradually evolve and improve as the online resources become more sophisticated and manipulation-resistant. In this paper, we evaluate the effectiveness of three popular online resources in detecting phishing sites-viz, Google PageRank system, Yahoo! Inlink data, and Yahoo! directory service. Our results indicate that these online resources can be used to increase the accuracy of phishing site detection when used in conjunction with existing phishing countermeasures. The proposed approach involves examining the following three attributes of a target site (site being examined): (1) the credibility of the target sitepsilas hosting domain, (2) the credibility of in-neighbor sites that link to the hosting domain, and (3) the correlation between the target sitepsilas web category and its hosting domainpsilas web category. The aforementioned online resources by themselves are insufficient to address the phishing attack problem. We provide discussions on how each of those resources may be integrated with existing phishing detection techniques to provide a more effective solution.
Keywords :
Web sites; computer crime; search engines; Google PageRank system; Web-based information theft; Yahoo! Inlink data; Yahoo! directory service; external online resources; hosting domain Web category; online resources evaluation; online transactions; phishing countermeasures; phishing site detection; target site Web category; user sensitive information; Application software; Finance; Information systems; Insurance; Internet; Uniform resource locators; World Wide Web;
Conference_Titel :
Applications and the Internet, 2009. SAINT '09. Ninth Annual International Symposium on
Conference_Location :
Bellevue, WA
Print_ISBN :
978-1-4244-4776-3
Electronic_ISBN :
978-0-7695-3700-9
DOI :
10.1109/SAINT.2009.14